{"id":"MGASA-2020-0233","summary":"Updated log4net packages fix security vulnerability","details":"Updated log4net packages fix security vulnerability\nThis patch fixes a security vulnerability reported by Karthik\nBalasundaram. The security vulnerability was found in the way\nhow log4net parses xml configuration files where it allowed to\nprocess XML External Entity Processing. An attacker could use \nthis as an attack vector if he could modify the XML configuration file.\n","modified":"2026-05-16T06:30:05.832553599Z","published":"2020-05-27T09:52:46Z","upstream":["CVE-2018-1285"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2020-0233.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=26608"},{"type":"WEB","url":"https://www.debian.org/lts/security/2020/dla-2211"},{"type":"WEB","url":"https://github.com/apache/logging-log4net/commit/d0b4b0157d4af36b23c24a23739c47925c3bd8d7"}],"affected":[{"package":{"name":"log4net","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/log4net?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.8-2.1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2020-0233.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}